In January 2026, Grubhub confirmed that unauthorized individuals had downloaded data from certain company systems, while stating categories such as financial information and order history were not affected. Coverage described engagement with forensics and law enforcement and noted extortion narratives involving the group ShinyHunters, including alleged pressure tied to both older Salesforce-era claims and newer Zendesk support data—often discussed alongside the Salesloft Drift OAuth/token theft wave.
Canonical record: Grubhub 2026 on BreachHistory (distinct from prior Grubhub breach years in the database).
Sources: BleepingComputer